BitBucket²ÎÊý×¢ÈëÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-09-23¡ñÎó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-15000£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
¡ñÓ°Ïì°æ±¾
version < 5.16.10
6.0.0 <= version < 6.0.10
6.1.0 <= version < 6.1.8
6.2.0 <= version < 6.2.6
6.3.0 <= version < 6.3.5
6.4.0 <= version < 6.4.3
6.5.0 <= version < 6.5.2
¡ñÎó²î¸ÅÊö
Atlassian Bitbucket ServerºÍAtlassian Bitbucket Data Center¶¼ÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£Atlassian Bitbucket ServerÊÇÒ»¿îGit´úÂëÍйܽâ¾ö¼Æ»®¡£¡£¡£¡£¡£¸Ã¼Æ»®Äܹ»ÖÎÀí²¢Éó²é´úÂ룬£¬£¬£¬£¬£¬¾ßÓвî±ðÊÓͼ¡¢JIRA¼¯³ÉºÍ¹¹½¨¼¯³ÉµÈ¹¦Ð§¡£¡£¡£¡£¡£Atlassian Bitbucket Data CenterÊÇAtlassian BitbucketµÄÊý¾ÝÖÐÐİ汾¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬Atlassian ¹Ù·½Ðû²¼Á˹ØÓÚAtlassian BitbuckeÎó²îͨ¸æ£¬£¬£¬£¬£¬£¬Atlassian Bitbucket ServerºÍAtlassian Bitbucket Data CenterÖб£´æ×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÏòGitÏÂÁî×¢ÈëÌØÁíÍâ²ÎÊý£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£¡£¡£ÈôÊÇÔ¶³Ì¹¥»÷ÕßÄܹ»»á¼ûBitbucket Server»òBitbucket Data CenterÖеÄGit´æ´¢¿â£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔʹÓô˲ÎÊý×¢ÈëÎó²î¡£¡£¡£¡£¡£ÈôÊÇΪÏîÄ¿»ò´æ´¢¿âÆôÓÃÁ˹«¹²»á¼û£¬£¬£¬£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔÄäÃûʹÓôËÎó²î¡£¡£¡£¡£¡£
¡ñÎó²îÑéÖ¤
ÔÝÎÞPOC¡¢EXP¡£¡£¡£¡£¡£
¡ñÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://jira.atlassian.com/browse/BSERV-11947
¡ñ²Î¿¼Á´½Ó
https://jira.atlassian.com/browse/BSERV-11947
https://confluence.atlassian.com/bitbucketserver/bitbucket-server-security-advisory-2019-09-18-976762635.html